CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Yearly Trend
Top Affected Vendors
All Out-of-bounds Write CVEs (2,742)
This vulnerability allows remote attackers to execute arbitrary code or cause denial of service through heap corruption by tricking users into visitin...
Aug 20, 2025This CVE describes an out-of-bounds write vulnerability in the Skia graphics library. Successful exploitation could allow attackers to write beyond al...
Aug 6, 2025This vulnerability allows attackers to execute arbitrary code or cause denial of service on Dell systems with vulnerable ControlVault firmware. An out...
Jun 13, 2025MicroDicom DICOM Viewer has an out-of-bounds write vulnerability that could allow remote attackers to execute arbitrary code. Users are affected if th...
Jun 10, 2025This vulnerability allows remote attackers to execute arbitrary code or cause denial of service through heap corruption by tricking users into visitin...
May 27, 2025This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the WiFi guest configu...
May 8, 2025This vulnerability allows authenticated attackers to execute arbitrary code on TOTOLINK NR1800X routers via a stack overflow in the setWiFiEasyGuestCf...
May 8, 2025This vulnerability allows a remote attacker to trigger heap corruption in Google Chrome's DevTools through out-of-bounds memory access. An attacker co...
May 5, 2025MicroDicom DICOM Viewer contains an out-of-bounds write vulnerability (CWE-787) that allows arbitrary code execution when a user opens a malicious DCM...
May 1, 2025This vulnerability allows remote attackers to execute arbitrary code on affected WinZip installations by tricking users into opening malicious 7Z file...
Feb 11, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of PDF-XChange Editor by tricking users in...
Feb 11, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious JPF files in Tungsten Automation Power P...
Feb 11, 2025This vulnerability in MediaTek wlan AP driver allows remote attackers within wireless range to execute arbitrary code without authentication or user i...
Feb 3, 2025This is a critical buffer overflow vulnerability in ChargePoint Home Flex charging stations that allows attackers on the same network to execute arbit...
Jan 31, 2025CVE-2018-9373 is a critical vulnerability in MediaTek's WLAN driver that allows remote attackers to execute arbitrary code without user interaction. T...
Jan 28, 2025This vulnerability allows remote attackers to execute arbitrary code on affected systems without user interaction by exploiting an integer overflow in...
Jan 21, 2025This vulnerability allows remote attackers to execute arbitrary code on Android devices via Bluetooth without user interaction. It affects Android dev...
Jan 21, 2025This vulnerability allows remote attackers to execute arbitrary code on Tenda AC18 routers via a stack overflow in the formSetCfm function. Attackers ...
Jan 16, 2025This vulnerability allows non-privileged user applications to make improper GPU system calls through Imagination Technologies GPU drivers, causing pla...
Jan 13, 2025This vulnerability in OpenHarmony allows a local attacker to perform an out-of-bounds write that can cause the device to become unbootable. It affects...
Jan 7, 2025This vulnerability allows remote attackers to execute arbitrary code within Chrome's sandbox via a crafted HTML page due to out-of-bounds memory acces...
Dec 18, 2024This vulnerability allows remote attackers to execute arbitrary code within Chrome's sandbox by exploiting an out-of-bounds write in the V8 JavaScript...
Dec 18, 2024CVE-2018-9413 is an out-of-bounds write vulnerability in Android's Bluetooth stack that could allow remote code execution when processing Bluetooth AV...
Dec 2, 2024CVE-2018-9380 is an out-of-bounds write vulnerability in Android's Bluetooth L2CAP protocol implementation that could allow remote code execution. Att...
Dec 2, 2024A WebGL vulnerability in Apple silicon M series devices allows out-of-bounds writes and memory corruption through Apple's GPU driver. This affects Fir...
Nov 26, 2024CVE-2018-9470 is an out-of-bounds write vulnerability in Android's Scanner.c that allows remote privilege escalation. Attackers can exploit this by tr...
Nov 20, 2024This vulnerability allows remote attackers to execute arbitrary code via Bluetooth on Android devices with SIP calling enabled. It affects Android dev...
Nov 20, 2024This vulnerability in Android's ClearKey CAS plugin allows remote attackers to execute arbitrary code through an out-of-bounds write during decryption...
Nov 19, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda G3 routers via a stack overflow in the formSetPortMapping function. Atta...
Nov 13, 2024This critical vulnerability in Google Chrome's Dawn component allows remote attackers to write data outside intended memory boundaries via a malicious...
Oct 29, 2024This vulnerability in Chrome's V8 JavaScript engine allows attackers to corrupt the stack through specially crafted HTML pages, potentially leading to...
Sep 17, 2024This vulnerability allows a remote attacker to execute arbitrary code or cause heap corruption in Google Chrome by tricking users into visiting a mali...
Sep 3, 2024This buffer overflow vulnerability in Tenda FH1206 routers allows attackers to execute arbitrary code by sending specially crafted requests to the for...
Aug 23, 2024This vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption through malicious HTML pages. Successful exploitation ...
Aug 21, 2024An out-of-bounds write vulnerability in Intel Ethernet Network Controller drivers allows authenticated local users to write beyond allocated memory bo...
Aug 14, 2024This vulnerability in Chrome's V8 JavaScript engine allows attackers to trigger heap corruption through malicious HTML pages. All users running vulner...
Aug 6, 2024This vulnerability allows remote attackers to perform out-of-bounds memory writes via a crafted HTML page in Google Chrome's SwiftShader component. It...
Jul 16, 2024This vulnerability in Chrome's V8 JavaScript engine allows attackers to perform out-of-bounds memory access via malicious HTML pages. It affects all u...
Jul 16, 2024Delta Electronics CNCSoft-G2 software has a memory corruption vulnerability due to improper input validation. Attackers can exploit this by tricking u...
Jul 9, 2024This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...
Jul 9, 2024This vulnerability is a stack-based buffer overflow in Artifex Ghostscript's pdfi_apply_filter() function that can be triggered by a malicious PDF fil...
Jul 3, 2024This vulnerability in Artifex Ghostscript allows heap-based buffer overflow when processing PDF passwords containing null bytes. Attackers could poten...
Jul 3, 2024This vulnerability allows a malicious Factorio server to execute arbitrary code on connecting clients through specially crafted custom maps. Attackers...
Jun 29, 2024Dell PowerProtect DD versions contain an out-of-bounds write vulnerability that allows low-privileged remote attackers to execute arbitrary code. This...
Jun 26, 2024This vulnerability allows remote attackers to exploit heap corruption through out-of-bounds memory access in Chrome's Dawn component. Attackers can tr...
Jun 20, 2024A heap buffer overflow vulnerability in Google Chrome's Tab Strip component allows remote attackers to perform out-of-bounds memory reads via crafted ...
Jun 11, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code with root privileges on Sonos Era 100 smart speakers without authentica...
Jun 6, 2024This vulnerability is a heap buffer overflow in WebRTC within Google Chrome that allows remote attackers to potentially exploit heap corruption via a ...
May 30, 2024This vulnerability allows remote attackers to exploit heap corruption in Google Chrome by tricking users into performing specific UI gestures on a mal...
May 30, 2024This vulnerability is an out-of-bounds write in Chrome's Streams API that allows remote attackers to execute arbitrary code within the browser's sandb...
May 30, 2024About Out-of-bounds Write (CWE-787)
The product writes data past the end, or before the beginning, of the intended buffer.
Our database tracks 2,742 CVEs classified as CWE-787, with 635 rated critical and 1,894 rated high severity. The average CVSS score for Out-of-bounds Write vulnerabilities is 8.2.
External reference: View CWE-787 on MITRE CWE →
Monitor Out-of-bounds Write Vulnerabilities
Get alerted when new Out-of-bounds Write CVEs affect your infrastructure.
Start Monitoring Free